Rules

Risk Assessment Summary

Rule

Severity

Likelihood

Detectable

Repairable

Priority

Level

IDS00-JHighLikelyYesNo

P18

L1

IDS01-JHighProbableNoNo

P6

L2

IDS03-JMediumProbableNoNo

P4

L3

IDS04-JLowProbableNoNo

P2

L3

IDS06-JMediumUnlikelyYesNo

P4

L3

IDS07-JHighProbableYesNo

P12

L1

IDS08-JMediumUnlikelyYesNo

P4

L3

IDS11-JHighProbableNoNo

P6

L2

IDS14-JHighProbableNoNo

P6

L2

IDS16-JHighProbableYesNo

P12

L1

IDS17-JMediumProbableNoNo

P4

L3



10 Comments

  1. Marc Peña

    I noticed that IDS01-J. Normalize strings before validating them is missing from the the rules index.

    1. David Svoboda

      Good catch, I've fixed it.

  2. Alexandre GIGLEUX

    Hello,

    1. IDS00-J is duplicated in the "Risk Assessment Summary". I believe we should keep only the first row having Level = L1

    2. Why are there only 8 entries in the "Risk Assessment Summary" table while there are 17 entries in the "Rule 00" category?

    Thanks

    1. Derek Leung

      Hi Alexandre,


      1. Thanks for the heads up on IDS00-J, we've removed the duplicate.
      2. An entry in the "Risk Assessment Summary" table is only added if the rule/rec is not a stub, not deprecated, and is complete. For example, IDS13-J is deprecated, so it doesn't have an entry in the table.
  3. Ahmed Shah

    Hello,
    If IDS14-J (IDS14-J. Do not trust the contents of hidden form fields) is complete should the "Risk Assessment" of IDS14-J be added this "Risk Assessment Summary"?

    1. David Svoboda

      Fixed.

  4. Markus Elfring

    How often would you like to use the word “Likely” (in the column “Likelihood”)?

    1. David Svoboda

      Unlikely (smile). I would rather that most rules were unlikely...eg. it would be very unlikely for a weakness to be exploited.

      1. Markus Elfring

        Does the text “Likelhy” indicate a typo here?

        1. David Svoboda

          Fixed, thanks.